Skip to main content
Evident ICU

Security & privacy

Private records should not become public product material.

The public site is separated from operational evidence systems. Examples on this surface are synthetic. This page describes governing posture, not a certification or a guarantee about every deployed control.

Governing principles

Minimize exposure. Separate authority. Preserve an audit path.

Separation

Public is not operational

The marketing surface must not directly read private evidence, operator notes, or core operational tables.

Least exposure

Publish only what is needed

Public examples use synthetic content and avoid personal identifiers, case facts, addresses, and private strategy.

Attribution

Review has an owner

Publication, correction, and handling decisions are designed to remain attributable rather than anonymous.

Originals

Preserve source bytes

The governing policy protects original bytes and keeps transformed artifacts in separate, traceable records.

Access

Private by default

Administrative and evidence-bearing surfaces should require authenticated, least-privilege access.

Disclosure

State what is unverified

Live retention, deletion, encryption, availability, and incident-response behavior require environment-level verification.

What this build verifies

Public-source controls, not production assurances.

  • The canonical public origin is https://evident-icu.com.
  • The public brand contract uses the Scale-v5 identity and bounded claims.
  • The flagship capability contract requires preserved original bytes and human review.
  • The public build enforces brand-contract and flagship-capability checks; private-path and sensitive-content leakage scans are available as separate audit tooling, not yet wired into the production build pipeline.
  • Administrative, dashboard, and evidence routes are excluded from search-crawler indexing instructions.

What this page does not verify

Live controls require live evidence.

  • Availability, durability, backup recovery, retention, or deletion outcomes.
  • Production encryption configuration or key-management effectiveness.
  • Authentication, authorization, billing, storage, or upload behavior in a deployed environment.
  • Compliance with a specific law, regulation, contract, or evidentiary rule.
  • Security against every threat or suitability for a particular matter.

Responsible contact

Report a security concern privately.

Do not send evidence, credentials, private records, or exploit details through public issue trackers.